What is the purpose of audit trails under PCI DSS?
- A.To track software license compliance, which needs to capture administrator actions only, since ordinary user activity is out of scope for audit trails
- B.To record and link all access to system components and cardholder data to individual users for accountability and forensic investigation
- C.To monitor network bandwidth usage given that failures of critical security control systems need reporting only at the annual assessment
- D.To track employee attendance, as audit trails need protecting only for systems that store the primary account number for SAQ D merchants
Why B is correct
Audit trails provide a chronological record of system activities, enabling reconstruction of events, detection of unauthorized access, and forensic investigation of security incidents involving cardholder data.
Know someone studying for PCI DSS? Send them this one.